Maiken Dueholm Sundahl, Group DPO and Compliance Officer at Norstedts Juridik and Karnov Group, points out that many organizations in the legal field are currently dealing with similar challenges regarding privacy, governance, legal quality, and the responsible use of artificial intelligence. The main challenge, she says, is ensuring that AI supports legal work without weakening the legal methods and critical thinking that are essential to the profession. This includes managing broader risks associated with AI, such as privacy concerns, issues around client confidentiality, and the risk that lawyers might become too reliant on AI-generated content without proper checks or human oversight.
Sundahl notes that the way lawyers and law firms use AI varies significantly, depending on how mature the organization is and how willing it is to take risks. Some law firms are testing AI cautiously, while others have already embedded it into their daily routines. She explains that lawyers are becoming more aware of the difference between public AI tools and enterprise solutions. When lawyers understand how these tools work and use reliable ones, they can see how AI can speed up legal research and free up time for more complex legal analysis and reasoning.
Sundahl emphasizes that one of the biggest risks related to AI is ignorance. If employees do not fully understand how AI tools operate or how data is processed, the use of AI in law firms can lead to serious issues. A common misconception is that there is little difference between free, publicly accessible AI tools and enterprise solutions, which are bound by strict security measures and data protection agreements. This distinction is vital for lawyers handling sensitive and confidential information.
Sundahl points out that a junior lawyer might use ChatGPT to draft a document, while a senior partner might use another AI tool to summarize a court ruling. However, no one has explicitly told them not to do this or explained what happens to the data they input. The consequences can be severe, including the accidental exposure of confidential client information, weakened professional confidentiality, and a loss of client trust. If a client discovers their information was input into a public AI tool, trust can quickly erode. Employees are not necessarily acting recklessly, but without proper training and understanding of how these tools function, organizations risk exposing themselves to unmeasured risks.
Sundahl highlights that legal methodology and source criticism are more important than ever. AI-generated responses can be very convincing, even when incorrect. She stresses the importance of maintaining critical thinking and legal methodology when working with AI. Even if the source is accurate, the interpretation might be wrong. Generative AI systems are designed to express themselves clearly and confidently, but lawyers must verify sources, evaluate reasoning, and apply professional judgment. The concept of a "human in the loop" becomes central in this process.
She explains that tasks such as proofreading, categorization, summarizing, and initial legal research are good examples of where AI can help lawyers process information more quickly, while leaving the responsibility of reasoning and conclusions to the lawyer. The danger arises when organizations treat AI-generated content as if a legal judgment has already been made. It is therefore essential to maintain legal methodology, source criticism, and the presence of a human in the process when using these tools.
Sundahl notes that law firms that succeed in the coming years will be those that invest in integration, training, governance, and building a strong internal culture around responsible AI use. A strong and continuous integration and awareness structure is crucial. A short training session is not enough. Lawyers must understand how to use the tools and how to maintain a critical perspective on their results. Integration should not be limited to features or options. It is also necessary to understand the limits of AI and know how to compensate for them with good processes, fact-checking, and a genuine "human in the loop" approach.
Creating a culture where employees feel confident in questioning AI-generated responses is equally important. Sundahl explains that it is important to normalize the idea that AI can make mistakes. Employees should feel comfortable asking questions, challenging results, and questioning how certain conclusions were reached. This approach should also be applied when working with AI.
For law firms, this means realizing that AI governance cannot be solved by a simple policy. Different tools, areas of law, and uses require different levels of supervision and control. Sundahl explains that law firms need both general governance principles and practical guidelines tailored to different use cases. There may be areas where the use of AI is more widely acceptable, and others where the risk appetite is lower. There is also a big difference between public tools and professional solutions, where data is protected and not used to train models.
Overall, Sundahl believes that law firms that will succeed in the coming years are those that have understood that AI is not just a technology issue but also a legal quality, governance, and professional responsibility issue. She concludes that successful law firms will be those that accept to invest the time and resources necessary to train their users, while understanding the limits of the technology. AI can create significant value, but only if solid legal analysis and human judgment remain at the heart of the process.
Lamy Liaisons has launched LamyLia Connect, a deliverables production solution that integrates the Lamy Liaisons document fund and the LamyLia legal AI technology directly into the workflow to multiply legal production quality and capacity.
Legal Industry Grapples with AI Integration, Privacy Risks, and Governance Challenges
AI-rewritten from original reportingHow it works
ai-in-lawlegal-aidata-privacylegal-governancelaw-firmsai-risks



